Ireland’s Data Protection Commission (DPC) has fined Google €403 million for breaching the EU’s GDPR by unlawfully and unfairly processing users’ location data. The probe, opened in 2020 and covering May 2018 to February 4, 2020, found problems across three features - web and app activity, location history and location accuracy - that meant users could be unaware their location was being used to profile them, influence ads or infer interests. The DPC gave Google six months to remedy the issues; Google says the case concerns historical policies it has since revised, pointing to 2019 onward changes including auto-deletion options (three to 36 months), on-device storage for Maps Timeline data and simplified controls over ad personalization, and may appeal parts of the ruling.
Regulators and consumer groups stress the stakes because location data can disclose sensitive matters such as religion, health or political views. The €403 million penalty is the DPC’s fourth largest under GDPR, after major fines for Meta, TikTok and Instagram. The decision followed a coordinated complaint led by the European Consumer Organisation (BEUC) alongside eight national consumer groups, which praised the outcome but faulted the slow pace of enforcement. The DPC is also pursuing three other large-scale inquiries into Google that are at an advanced stage.
Summary generated by AI from the linked article. hn.today is not affiliated with Hacker News or Y Combinator.